Unauthorized Access in Apache Solr Due to Input Validation Flaw
CVE-2026-22022
8.2HIGH
What is CVE-2026-22022?
Apache Solr versions 5.3.0 to 9.10.0 are at risk of unauthorized access through insufficient input validation in the Rule Based Authorization Plugin. This security issue arises when deployments utilize multiple roles and predefined permission rules but do not specify the 'all' permission. Additionally, if the network setup allows unmonitored client requests to Solr, the vulnerability becomes exploitable. Organizations are advised to review their configurations to ensure security and upgrade to an unaffected version, such as 9.10.1, to bolster their defenses.
Affected Version(s)
Apache Solr 5.3 <= 9.10.0